Re: BlackIce IDS

From: svek (svek-NO-SPAM@gmx.net)
Date: 01/08/03


From: svek <svek-NO-SPAM@gmx.net>
Date: 8 Jan 2003 21:10:20 GMT


"Duane Arnold" <nitme@notme.com> wrote in
news:mP%S9.287877$qF3.27603@sccrnsc04:

> If I set BlackIce on a machine at home to Accept all my company's
> IP(s) on ports used by Netmeeting and connect Netmeeting to Netmeeting
> RDS to a machine at work that is infected with worm, I know that IDS
> is going to see that attack coming and is going to instruct the
> firewall to start blocking network traffic from that IP.
>
> Any of the rest of the firewalls doing that let me know.

Well, security is larger than protecting against those vulnerabilities that
are known. What if this worm would be something new, one of a kind?
All BlackIce can do is to compare signatures to patterns in the network
traffic, but what if there wasn't any pattern like this one before?
Then that trust could be easily exploited.
An IP address is by no mean a way to identify yourself by, just look at the
r* services history.

/svek



Relevant Pages

  • Re: Ping pmj
    ... a software firewall to fill the gaps in or you will get intruders!!! ... Software Firewall, or not Forwarded in your Router), then NetMeeting ... *also* Open up some Ports when receiving Calls. ... Such as VNC ...
    (uk.people.silversurfers)
  • Re: Netmeeting works but nothing else does
    ... "Full" NetMeeting calls are really two calls in parallel - and H.323 ... > connections on specific ports and secondary UDP connections on ... > computers outside the firewall and you are able to use the audio ...
    (microsoft.public.internet.netmeeting)
  • Re: Tutorial?
    ... I am building a visual basic application that uses Netmeeting SDK. ... if you just use the remote desktop thing. ... It depends on what "opening" ports means though and what kind of firewall ... incoming or outgoing calls. ...
    (microsoft.public.internet.netmeeting)
  • Re: Problems with Netmeeting
    ... My friend uses Windows ME. ... assuming the party is running NetMeeting waiting for the call, ... router or firewall or protected by a local software firewall that blocks ...
    (microsoft.public.internet.netmeeting)
  • RE: NetScreen XP and NetMeeting
    ... Let me preface this by saying I know nothing about Netmeeting, ... Are you a client connecting to the internet through a firewall and trying to ... establish a netmeeting connection, or are you setting up a Netmeeting server ... The big scary-looking range of ports are outbound UDP ports, ...
    (Security-Basics)